Skip to content
Review Open access

Advanced Security through Hardware Capabilities: A Comprehensive Survey on CHERI Technology

Aug 2026 · ACM Computing Surveys · Vol 58, pp. 1 - 36 · 0 citations · 215 references

TL;DR

A detailed survey of CHERI technology is provided, covering its historical evolution, key concepts, and current hardware and software implementations, and the ongoing challenges of its adoption in industry, the research efforts driving its growth as well as speculating and discussing future research directions.

Abstract

As next-generation systems become increasingly complex and interconnected, they face the burden of new and numerous critical security challenges. Capability Hardware Enhanced RISC Instructions (CHERI) has emerged as a promising technology to mitigate memory safety vulnerabilities, one of the major security threats in current computing systems. CHERI introduces a hardware-enforced, fine-grained memory protection model that integrates a fat-pointer representation, combining memory bounds and permissions to ensure safer memory access and mitigate common memory-related exploits. Despite its potential, information about CHERI evolution, design principles, and applications is scattered among multiple sources, making it difficult to fully grasp and correlate its features and applications. This article aims to fill such gap by providing a detailed survey of CHERI technology, covering its historical evolution, key concepts, and current hardware and software implementations. We explore the ongoing challenges of its adoption in industry, the research efforts driving its growth as well as speculating and discussing future research directions.

Read PDF

Similar papers

Review Open access Aug 2026

Advancements in memory-based cryptographic physical unclonable functions: a comprehensive review and future directions

With lightweight hardware security becoming increasingly critical for Internet of Things devices, Physical Unclonable Functions (PUFs) have emerged as a key enabling technology, providing device authentication, cryptographic key generation, and simplified key management capabilities without requiring dedicated on-chip...

Peizhen Hong, Zhixin Ren, Gui-Qin Li et al. · 0 citations
Review

SoK: From Silicon to Netlist and Beyond Two

Stakeholder-specific recommendations for academia, industry, and government to transition HRE from isolated research silos toward a collaborative discipline capable of assuring increasingly complex, global hardware supply chains are derived.

Zehra Karadağ, Simon Klix, René Walendy et al. · 0 citations
Open access Sep 2026

Lattice: Enabling Scalable Enclaves for Commercial RISC-V Platforms

Trusted Execution Environments (TEEs) have been extensively adopted to facilitate various security-critical applications. However, in stark contrast to well-established TEE technologies such as Intel SGX, AMD SEV, and ARM TrustZone, the adoption within the emerging RISC-V architecture has seen limited traction. Specifi...

Yu Zhao, Jia-Bei He, Ming-Ru Xu et al. · 0 citations
Review Open access Sep 2026

SoK: From Silicon to Netlist and Beyond

This work presents the first large-scale Systematization of Knowledge of Knowledge of the HRE workflow, analyzing 187 peer-reviewed publications and derives stakeholder-specific recommendations for academia, industry, and government to transition HRE from isolated research silos toward a collaborative discipline capabl...

Zehra Karadağ, Simon Klix, René Walendy et al. · 0 citations
Preprint Aug 2026

SoK: ARCUS: On the Efficiency and Efficacy of Hardware Fuzzing

This work presents a comprehensive analysis of contemporary hardware fuzzing techniques applied across three major abstraction layers: Instruction Set Architecture (ISA), microarchitecture, and Register-Transfer Level (RTL). Our study examines key factors including input stimulus quality, mutation strategies, feedback...

Alenkruth Krishnan Murali, Raghul Saravanan, D. SaiManojP et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.